Artificial intelligence has become a fixture on every executive agenda, but the nature of the conversation is changing. The focus has moved beyond chatbots and content generation towards Agentic AI: software that can pursue goals on its own, work with other systems and take decisions that would once have required a person.
For business leaders, the appeal is obvious. Autonomous agents can remove repetitive work, speed up operations and unlock services that were not previously practical. For identity and security teams, however, the same capabilities raise a pressing question that is receiving far less attention. If software can now act independently inside the business, how will anyone keep track of what it is doing, and who is answerable when it gets something wrong?
That question deserves an answer now, not after agents are already embedded in core processes. Forecasts suggest agents will be commonplace within the next three to five years. The organisations that benefit most will not necessarily be the earliest adopters. They will be the ones that can operate agents safely, securely and at volume.
The Assumption That No Longer Holds
For decades, identity security has depended on a quiet assumption: that the behaviour of an identity can be anticipated.
A human employee works within a role and follows policy. A scheduled job or integration script does exactly what its code tells it to do, every time. Access controls, approval processes and audit reviews were all designed around this kind of predictability.
Autonomous agents do not fit that pattern. They are given an objective rather than a set of instructions, and they work out their own route to reach it. They reason, respond to new information and change course midway through a task. Two agents given identical goals can produce entirely different sequences of actions.
Speed and scale compound the challenge. An agent can carry out hundreds or thousands of operations across applications and APIs within minutes. In multi-agent architectures, a single request might be broken into parts and handled simultaneously by several specialised agents, each touching different systems.
The consequence is a change in the core security task. Protecting access is no longer enough. Organisations now need to govern autonomous decision-making, and the identity tools most of them rely on were not designed with that in mind.
Three Generations of AI Agents
Understanding where agents are heading helps explain why the identity model has to change.
The first generation was the assistant. These tools answered questions and handled narrow requests, such as explaining a leave policy or retrieving a document from an internal knowledge base. They supported people but rarely took action in other systems.
The second generation, now appearing across many enterprises, is the autonomous agent. These agents complete multi-step tasks by working across several applications, often as one member of a team of agents that each specialise in a different part of the job. Consider an expenses workflow in which one agent reads receipts, another checks them against company policy, a third updates the finance system and a fourth notifies the employee, all without anyone stepping in.
The third generation is the digital worker. Here, agents become ongoing members of business teams, collaborating with people and other agents to deliver results. They absorb context, improve their approach over time, coordinate processes spanning many systems and can even create new tools when existing ones are not sufficient.
This third stage can sound speculative, but given how quickly AI capability is advancing, it is likely to arrive sooner than most planning cycles assume.
Where Current IAM Controls Struggle
Identity and Access Management has traditionally been built around the way people work. Someone authenticates, opens the applications they need and performs tasks their role allows. Governance reviews, approval workflows and logging keep risk in check, and the approach works because human activity is relatively slow and follows recognisable patterns.
Conventional machine identities, such as service accounts behind scheduled jobs, have been governed on similar terms because their actions are fixed and repeatable.
Autonomous agents strain this model in several places at once.
Permissions are the first pressure point. Many IAM deployments grant fairly broad access for the duration of a session. For a person, that is usually acceptable. For an agent capable of thousands of actions in that same window, broad session access represents a significant exposure.
Accountability is the second. When agents act using shared credentials or on behalf of users without distinct identities of their own, their activity becomes hard to separate from human activity. The audit trail loses its meaning, and basic questions about who performed an action and for what reason become difficult or impossible to answer.
Regulatory exposure is the third. In sectors such as banking, insurance and healthcare, organisations must be able to explain and evidence how decisions were made and who authorised them. An agent operating outside clear identity boundaries makes that very hard to demonstrate.
A Different Standard for Agent Identity
Addressing these gaps starts with how agents are classified. Treating them as just another category of machine account underestimates what they can do. A better approach is to regard each agent as a first-class identity, governed with the same care an organisation would apply to a privileged human user in a sensitive role.
That standard is built on five practical foundations.
Discovery
Discovery comes first. Security teams need a complete, continuously updated picture of every agent in the environment, including tools switched on by business units and pilots that never passed through formal review.
Ownership and Governance
Ownership and governance follow. Each agent should have a distinct identity, a written statement of what it is for and a named person who is accountable for its conduct throughout its lifecycle, up to and including retirement.
Controlled Connectivity
Controlled connectivity is the third foundation. Agents should reach applications and APIs through consistent, standardised channels rather than one-off integrations that each carry their own weaknesses.
Real-Time Authorisation
Real-time authorisation is the fourth. Rather than relying solely on permissions set in advance, each significant action an agent attempts should be assessed at that moment, using context such as the task, the data involved and the level of risk.
Continuous Oversight
Continuous oversight completes the picture. Organisations need to monitor agent behaviour at scale, recognise when it drifts from what is expected and be able to intervene quickly.
These five elements are what turn agent adoption from an open-ended risk into something manageable. For organisations formalising their approach, they provide a solid base for a broader Agentic AI Security programme that can grow as agent use expands.
Building the Foundation Before the Workforce
AI agents offer a genuine opportunity to change how work gets done, from automating complex processes to creating entirely new services. As with every major technology shift, though, lasting success depends less on how quickly organisations experiment and more on the foundations they establish.
The businesses that get the most from Agentic AI will be those that put a fit-for-purpose identity governance model in place early, so they can deploy autonomous systems with confidence rather than caution.
The principle is simple. Before digital workers join the organisation, the identity architecture needed to govern them must already be in place. For any leadership team exploring agents today, that work should begin alongside the first pilot, not after the hundredth deployment.